Missing Authentication for Critical Function in MikroTik RouterOS - CVE-2026-67277
Published: September 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose kernel memory and cause a denial of service.
The vulnerability exists due to missing authentication for a critical function in the RouterOS btest connection handling when accepting a related btest connection before primary-session authentication completes. A remote attacker can start an IPv4 UDP test with random-data disabled and use the unchecked packet-size interval to disclose kernel memory and cause a denial of service.